cbcvebase.
CVE-2009-2416
published 2009-08-11

CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
appleiphone_os>= 2.0 < 4.04.0
applemac_os_x< 10.4.1110.4.11
applemac_os_x>= 10.5.0 < 10.5.810.5.8
applemac_os_x>= 10.6.0 < 10.6.210.6.2
applemac_os_x_server< 10.4.1110.4.11
applemac_os_x_server>= 10.5.0 < 10.5.810.5.8
applemac_os_x_server>= 10.6.0 < 10.6.210.6.2
applesafari< 4.0.44.0.4
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibxml2< libxml2 2.7.3.dfsg-2.1 (bookworm)libxml2 2.7.3.dfsg-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 2.0.172.432.0.172.43
opensuseopensuse10.3 – 11.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
sunopenoffice.org>= 2.0.0 < 2.4.32.4.3
sunopenoffice.org>= 3.0.0 < 3.1.13.1.1
suselinux_enterprise
suselinux_enterprise

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM